Connection management method and device of service equipment, equipment, medium and program product
Patent Information
- Application Number
- CN202380094861.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-09
- Publication Date
- 2025-10-03
AI Technical Summary
In existing technologies, network connection management of service devices in the Internet of Things (IoT) presents challenges, especially in situations involving multiple security domains and complex network types, where it is difficult to effectively manage network access and connections for service devices.
By storing the management attributes of service devices in the gateway device, the gateway device manages the network connections of the service devices based on these attributes, thereby enabling network access control over the service devices.
It enables network connection management for service devices, ensuring the security and flexibility of network access and adapting to complex environments with multiple security domains and network types.
Smart Images

Figure CN120752906A_ABST
Abstract
Description
Service equipment connection management method, device, equipment, medium and program product Technical Field
[0001] The present application relates to the field of Internet of Things technology, and in particular to a method, apparatus, device, medium, and program product for connection management of a service device. Background Art
[0002] With the continuous development of Internet of Things (IoT) technology, more and more IoTs have brought great convenience to users' production and life in many fields such as smart homes and industrial production.
[0003] In related technologies, service devices in the Internet of Things establish network connections through gateway devices. How to manage the network connections of service devices is an urgent problem to be solved.
[0004] Summary of the Invention
[0005] The present invention provides a method, apparatus, device, medium, and program product for managing the connection of a service device. The technical solution is as follows:
[0006] In one aspect, an embodiment of the present application provides a connection management method for a service device, the method being performed by a gateway device, the method comprising:
[0007] The network connection of the service device is managed based on the management attributes of the service device in the gateway device.
[0008] In one aspect, an embodiment of the present application provides a connection management method for a service device, the method being performed by a first control device, the method comprising:
[0009] Adding management attributes of the service device to the gateway device, where the management attributes are used to manage the network connection of the service device.
[0010] On the other hand, an embodiment of the present application provides a connection management device for a service device, the device comprising:
[0011] A management module is used to manage the network connection of the service device, wherein the management is performed based on the management attributes of the service device in the gateway device.
[0012] On the other hand, an embodiment of the present application provides a connection management device for a service device, the device comprising:
[0013] The second sending module is configured to add management attributes of the service device to the gateway device, where the management attributes are used to manage the network connection of the service device.
[0014] On the other hand, an embodiment of the present application provides a computer device, which includes a processor, a memory and a transceiver, wherein the memory stores a computer program, and the computer program is used to be executed by the processor to implement the connection management method of the above-mentioned service device.
[0015] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is loaded and executed by a processor to implement the connection management method of the above-mentioned service device.
[0016] On the other hand, the present application also provides a chip, which is used to run in a computer device so that the computer device executes the connection management method of the above-mentioned service device.
[0017] In another aspect, the present application provides a computer program product, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the above-mentioned service device connection management method.
[0018] On the other hand, the present application provides a computer program, which is executed by a processor of a computer device to implement the connection management method of the above-mentioned service device.
[0019] The technical solutions provided in the embodiments of the present application can bring the following beneficial effects:
[0020] By storing the management attributes of the device in the gateway device, the gateway device manages the network connection of the service device according to the management attributes of the service device, thereby achieving network connection management of the service device and controlling the network access of the service device. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0022] FIG1 is a schematic diagram of a network architecture of the Internet of Things provided by one embodiment of the present application;
[0023] FIG2 is a schematic diagram of a firewall configuration according to an embodiment of the present application;
[0024] FIG3 is a schematic diagram of a Thread network provided by one embodiment of the present application;
[0025] FIG4 is a flow chart of a method for connection management of a service device provided by an embodiment of the present application;
[0026] FIG5 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0027] FIG6 is a flowchart of a method for connection management of a service device provided by an embodiment of the present application;
[0028] FIG7 is a schematic diagram of a connection management method for a service device provided by an embodiment of the present application;
[0029] FIG8 is a schematic diagram of a connection management method for a service device provided in one embodiment of the present application;
[0030] FIG9 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0031] FIG10 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0032] FIG11 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0033] FIG12 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0034] FIG13 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0035] FIG14 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0036] FIG15 is a flowchart of a method for managing a connection of a service device according to an embodiment of the present application;
[0037] FIG16 is a flowchart of a method for connection management of a service device provided by one embodiment of the present application;
[0038] FIG17 is a block diagram of a connection management apparatus for a service device provided by one embodiment of the present application;
[0039] FIG18 is a block diagram of a connection management apparatus for a service device provided by one embodiment of the present application;
[0040] FIG19 is a schematic structural diagram of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0041] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0042] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0043] Please refer to Figure 1, which shows a schematic diagram of a network architecture of the Internet of Things provided by an embodiment of the present application. The network architecture of the Internet of Things may include: a server device (Sever) 110, a control device (Client) 120, and a gateway device 140.
[0044] Service device 110 can be a device in the Internet of Things (IoT) that provides client functionality corresponding to IoT protocols. A service device can be a device that provides specific IoT services, such as a camera that provides video capture services. Service device 110 can also be referred to as an IoT device, or simply a device. A service device can provide subscribable resources.
[0045] For example, the service device 110 can be a smart home device, such as a smart lamp, a smart TV, a smart air conditioner, a smart refrigerator, a smart microwave oven, a smart rice cooker, a sweeping robot, a smart speaker, a smart switch, etc.
[0046] Alternatively, the service equipment 110 may be industrial production equipment, such as a lathe, an industrial robot, a solar panel, a wind turbine, and the like.
[0047] Alternatively, the service device 110 may be a commercial service device, such as an unmanned vending machine, etc.
[0048] Alternatively, the service device 110 may be an intelligent monitoring device, such as a monitoring camera, an infrared sensor, a sound sensor, a temperature sensor, and the like.
[0049] In one possible implementation, the service device 110 may also be a user-side terminal device. For example, the service device 110 may be a smart controller, a smart remote control, a smartphone, a tablet computer, a smart watch, a smart TV, a gateway, etc. Alternatively, the service device 110 may be a personal computer, such as a desktop computer, a portable computer, a personal workstation, etc.
[0050] The control device 120 may be a terminal device on the user side, for example, a smart phone, a tablet computer, a smart watch, a smart TV, etc.
[0051] In another possible implementation, the control device 120 may also be a client entity (which may be a virtual entity) running on a terminal device. For example, the control device 120 may be an APP running on a smart phone for managing and configuring the service device 110 .
[0052] The gateway device 140 may be a device installed in the Internet of Things (IoT) to provide information exchange, information maintenance, and other services to various service devices and control devices in the IoT. The gateway device 140 may also be called a home gateway, an access point (AP), a border router (BR), or the like.
[0053] The control device 120 may communicate with the gateway device 140 .
[0054] In some embodiments, the control device 120 is a device with management authority, and the control device 120 can be used to configure the gateway device.
[0055] In an embodiment of the present application, different service devices 110 may support the same or different IoT protocols. For example, different IoT protocols may include at least one of the following: the Matter protocol (or the Connected Home over IP Working Group, CHIP project) under the Connectivity Standards Alliance (CSA) (or Zigbee Alliance).
[0056] Matter is an IP-based IoT connectivity protocol that addresses compatibility, security, and connectivity issues currently facing the smart home market. Matter defines a technical solution for configuring devices, including steps such as device discovery, device authentication, device configuration, and device operation. The Matter protocol includes the following concepts:
[0057] 1. Fabric (security domain)
[0058] A fabric, also known as a woven network or ecological network, consists of a set of nodes that interact by accessing data model elements defined in an interaction model. A fabric is a security domain within which a set of nodes can be identified and communicate. A node is considered "in" a fabric when it can be identified and interacted with within that fabric. An interaction is considered "in" a fabric when it occurs within the fabric's scope. An interaction can occur within a specific fabric or be fabric-independent. When an interaction is associated with a specific fabric, it is understood to occur within that fabric; when an interaction is not associated with any fabric, it is understood to be fabric-independent and applicable to all fabrics. Interaction can be narrowly understood as the sending and receiving of data packets, or broadly understood as any form of network interaction between two nodes. A node can be identified and interact on one or more fabrics. The establishment of a fabric and the joining of nodes to it are defined by lower-layer specifications.
[0059] 1) Access Fabric
[0060] If an interaction is associated with a specific Fabric, then that Fabric is called the "visit Fabric". If an interaction is not associated with any Fabric, then there is no "visit Fabric". In this case, comparing the access Fabric with any existing Fabric should consider them unequal.
[0061] 2) Fabric-scoped (within a security domain) data
[0062] Most cluster ("functional set" or "cluster") data instances are operable regardless of whether the fabric is accessed. However, if the data is only relevant to a specific fabric, then the data should be defined as Fabric-scoped. Fabric-scoped data should be defined as Fabric-scoped features.
[0063] Then the Fabric associated with Fabric-scoped data is called "associated Fabric".
[0064] Fabric-scoped data allows multiple accessors to operate on a set of data items without affecting each other. See Fabric Filtered List for more information.
[0065] Fabric-scoped data should be limited to the following:
[0066] A list of Fabric-scoped structures;
[0067] Fabric-Sensitive events.
[0068] Fabric-scoped data instances are data instances similar to composite structures, which contain many fields.
[0069] Fabric-scoped data should always contain a FabricIndex (security domain index) field to specify the associated Fabric. The FabricIndex field of this Fabric-scoped data should not be 0 or null (invalid value).
[0070] Any interaction (including cluster commands) that accesses Fabric and the associated Fabric data is different should not modify Fabric-scoped data directly or indirectly, unless the cluster command explicitly states some exceptions.
[0071] If the data is Fabric-scoped, then it is very likely that all or part of the data is also Fabric-Sensitive.
[0072] 3) Fabric-Scoped List
[0073] A Fabric-scoped list should define a structure's item data type, which should also be Fabric-scoped.
[0074] Each item in the Fabric-scoped list should be applicable to a specific Fabric or no Fabric at all.
[0075] Fabric-scoped lists support a Fabric filter that filters read and write interactions on the list's view. This filter simplifies the logic of clients that do not want to read or write Fabric data that is not related to accessing Fabric.
[0076] Interactions on a fabric-filtered list should only indicate access entries for the relevant fabric that match the access fabric, while all other entries should be ignored.
[0077] Fabric filtered list entries should be in the same order as the full list.
[0078] Fabric filter list entries should be indexed starting from 0, with no gaps, as if other entries did not exist.
[0079] For write interactions, Fabric filtering should be enabled.
[0080] When writing to a Fabric-scoped list, the write interaction should be on an access Fabric, otherwise, the write interaction will fail.
[0081] For read interactions on lists, Fabric filtering can be enabled.
[0082] For read interactions on a list, if Fabric filtering is disabled, the list is reported as a complete list containing all entries.
[0083] Example: A complete list of Fabric-scoped items, where each item has an associated FabricIndex and Value fields:
[0084] list=[{FabricIndex=A,Value=20},
[0085] {FabricIndex=B,Value=30},
[0086] {FabricIndex=A,Value=40},
[0087] {FabricIndex=B,Value=50},
[0088] {FabricIndex=B,Value=60}]
[0089] When accessed using Fabric B, a Fabric filter list will be displayed:
[0090] list=[{FabricIndex=B,Value=30},
[0091] {FabricIndex=B,Value=50},
[0092] {FabricIndex=B,Value=60}]
[0093] Reading Fabric filter list entry index 2 accessed by Fabric B will report:
[0094] list[2]=[{FabricIndex=B,Value=60}]
[0095] When accessing using Fabric B, write the Fabric filtered list entry index 1:
[0096] list[1]=[{FabricIndex=B,Value=55}]
[0097] Change the full list to:
[0098] list=[{FabricIndex=A,Value=20},
[0099] {FabricIndex=B,Value=30},
[0100] {FabricIndex=A,Value=40},
[0101] {FabricIndex=B,Value=55},
[0102] {FabricIndex=B,Value=60}]
[0103] 2. Definition rules of AP firewall
[0104] As shown in Figure 2, after setting the AP's firewall rules, the AP can manage (allow 101 or block) the network connection of the service device (including the ability to access the WAN and the ability to access the LAN).
[0105] 3. Network type
[0106] 1) WAN (Wide Area Network). WAN is the largest type of network. A WAN can include multiple LANs (Local Area Networks), CANs (Campus Area Networks), and MANs (Metropolitan Area Networks). It is a network that spans a large geographical area, such as a country, a continent, or even the entire earth. A good example of a WAN is the Internet.
[0107] 2) LAN (Local Area Network) consists of a group of devices such as computers, servers, switches, printers, etc. The most common type of LAN is Ethernet, where two or more computers are connected to an Ethernet switch via cables.
[0108] 3) PAN (personal area network), including:
[0109] Wireless connection: Bluetooth, infrared, NFC;
[0110] Wired connection: USB cable;
[0111] Commonly used to transfer small files such as music, photos, calendars, appointments, etc.
[0112] The network formed using Thread can be a PAN. In some embodiments, the PAN can be formed using a Thread network.
[0113] Thread Network
[0114] Users communicate with the Thread network from their own devices (smartphones, tablets, or computers) via Wi-Fi on their LAN or using cloud-based applications. For example, Figure 3 illustrates the main types of devices in a Thread network.
[0115] The Thread network includes the following device types:
[0116] Border Router 201: Supports connectivity between the Institute of Electrical and Electronics Engineers (IEEE) 802.15.4 network and other adjacent physical layer networks (Wi-Fi, Ethernet, etc.). The Border Router provides services to devices within the IEEE 802.15.4 network, including routing services and service discovery in offline scenarios. A Thread network can have one or more Border Routers.
[0117] Leader 202: Located in the Thread network, it manages the allocation and registration of router IDs and accepts requests from router-eligible end devices (REEDs) to become routers. The Leader decides which devices should be routers and, like all routers in the Thread network, can have children. The Leader also allocates and manages router addresses via CoAP (Constrained Application Protocol). However, all information contained in the Leader is also stored in other Thread routers. Therefore, if the Leader fails or loses connection to the Thread network, another Thread router can be elected as the Leader without user intervention.
[0118] Thread Router 203: Provides routing services for network devices. Thread Routers also provide joining and security services for devices attempting to join the network. Thread Routers cannot sleep and can be downgraded to become REEDs.
[0119] Router-Eligible End Device (REED) 204: Can become a Thread router or leader, but is not necessarily a border router with special properties (such as multiple interfaces). A REED cannot become a router under certain network topologies or other circumstances. A REED does not relay messages or provide joining or security services to other devices in the network. If necessary, the network manages and upgrades router-eligible devices to router status without user intervention.
[0120] End Device: End devices that do not qualify as routers can be Full End Devices (FEDs) or Minimal End Devices (MEDs). MEDs can communicate without synchronizing with a parent device.
[0121] Sleepy End Devices (SEDs): These devices communicate only through the Thread router parent and cannot relay messages for other devices.
[0122] Synchronized Sleepy End Devices (SSED): A type of sleepy end device that uses the Coordinated Sampled Listening (CSL) protocol in IEEE 802.15.4-2015 to synchronize with its parent device without using regular data requests.
[0123] Please refer to FIG4 , which shows a flow chart of a method for connection management of a service device provided by one embodiment of the present application. The method may be performed by a gateway device, for example, the gateway device may be the gateway device 140 in the network architecture shown in FIG1 . The method may include the following steps:
[0124] Step 210: Manage the network connection of the service device. The management is performed based on the management attributes of the service device in the gateway device.
[0125] Optionally, the gateway device manages the network access of the service device, and the management is performed based on the management attributes of the service device in the gateway device.
[0126] A service device may also be referred to as an IoT device, a station (STA) device, a Matter STA device, or simply a device. Optionally, the service device is an IoT device that supports the Matter protocol. Optionally, the service device belongs to at least one security domain (Fabric). Optionally, the service device may also be a non-Matter device (IoT device) that does not support the Matter protocol.
[0127] A gateway device can also be called a home gateway, access point, or Matter AP. The gateway device belongs to at least one security domain. Optionally, the gateway device and the service device belong to at least one of the same security domains. For example, both the gateway device and the service device belong to the first security domain; or, for another example, both the gateway device and the service device belong to the first security domain and the second security domain.
[0128] The control device can also be called an administrator device, management device, configuration device, or management terminal. The control device belongs to at least one security domain. Optionally, the gateway device, service device, and control device all belong to at least one same security domain. For example, the gateway device, service device, and control device all belong to the first security domain, and the control device has management authority within the first security domain.
[0129] The management attribute may also be referred to as at least one of a management policy, a device connection management attribute, a device connection management policy, a blacklist management attribute, a blacklist device management attribute, a blacklist management policy, and a blacklist device management policy.
[0130] Optionally, the management attributes are stored in a connection management list of the gateway device. Alternatively, the management attributes are stored in a network management function set (Network Management Cluster) of the gateway device. The gateway device manages the network connection / network access of the service device based on the connection management list / network management function set.
[0131] Management attributes include at least one of the following parameters:
[0132] Target node, used to indicate the identification information of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0133] The target node includes the node identifier of the service device in the security domain. Each node in the security domain has a corresponding node identifier. The same service device may have different node identifiers in different security domains. For example, the service device may have a first node identifier in the first security domain and a second node identifier in the second security domain. Node identifiers are used to identify nodes within a security domain.
[0134] The target device may include at least one of an IP (Internet Protocol) address and a MAC (Media Access Control Address) address (physical address) of the service device.
[0135] The target security domain includes a security domain identifier. Different security domains have different security domain identifiers. The target security domain is the identifier of the security domain to which the managed device belongs. Alternatively, the target security domain is the identifier of the security domain to which the control device (first control device) is located.
[0136] The connection type includes at least one of the following: a wide area network (WAN); a local area network (LAN); or a personal area network (PAN).
[0137] The behavior includes at least one of the following: Refuse (blocking) and returning a connection error; Drop (blocking) without returning a connection error; Allow (Accept / Allow). Alternatively, the behavior includes at least one of the following: Block; Allow (Accept / Allow).
[0138] Alternatively, the behavior includes at least one of the following: Refuse, i.e., blocking, and returning a connection error to the service device (IoT device) that initiated the connection request; Drop, i.e., blocking, and not returning a connection error to the service device (IoT device) that initiated the connection request; Accept / Allow.
[0139] For example, when the management attributes include: the target node is 001, the target device is 002, the target security domain is 003, the connection type is WAN, the access address is www.xxx.com, and the behavior is blocking; the gateway device blocks the first service device from accessing www.xxx.com in the WAN according to the management attributes, wherein the first service device is the 001 node in the 003 security domain, and the device address is 002.
[0140] In an optional embodiment, when the management attributes do not include behavior, the default setting is blocking. And / or when the management attributes do not include access addresses, the default setting is all access addresses of the connection type.
[0141] For example, when the management attribute includes access address and behavior, management includes: allowing or blocking the service device's access to the access address according to the behavior. When the management attribute includes access address (excluding behavior), management includes: blocking the service device's access to the access address.
[0142] For another example, if the management attribute does not include an access address but includes a behavior and a connection type, management includes: allowing or blocking the service device's access to all access addresses of the connection type based on the behavior. If the management attribute does not include an access address but includes a connection type (but not a behavior), management includes: blocking the service device's access to all access addresses of the connection type.
[0143] Optionally, the device whose network connection is managed may also be another gateway / bridge device; that is, replace "service device" with "other gateway / bridge device": the network connection of the other gateway / bridge device is managed based on the management properties of the other gateway / bridge device in the gateway device. For example, the main gateway manages the network connection of the sub-gateway based on the management properties of the sub-gateway in the main gateway.
[0144] In summary, by storing the management attributes of the device in the gateway device, the gateway device manages the network connection of the service device according to the management attributes of the service device, thereby achieving network connection management of the service device and controlling the network access of the service device.
[0145] Please refer to FIG5 , which shows a flow chart of a method for connection management of a service device provided in one embodiment of the present application. The method may be performed by a first control device, for example, the first control device may be the control device 120 in the network architecture shown in FIG1 . The method may include the following steps:
[0146] Step 310: Add management attributes of the service device to the gateway device. The management attributes are used to manage the network connection of the service device.
[0147] Optionally, the management attribute may include at least one of a connection management attribute (also referred to as a "device connection management attribute (DeviceConnectMgmt)") and a blacklist management attribute (DenyList).
[0148] Connection management attributes are used to manage connection access for service devices on the network. Blacklist management attributes are used to manage the connection access blacklist for service devices on the network. For example, connection management attributes include actions, while blacklist management attributes do not. The default action for blacklist management attributes is block.
[0149] Optionally, the default behavior of the blacklist management attribute may be at least one of the following: Refuse, ie, blocking and returning a connection error; Drop, ie, blocking without returning a connection error.
[0150] Alternatively, the default behavior of the blacklist management attribute can be at least one of the following: Refuse, i.e., block, and return a connection error to the service device (loT device) that initiates the connection request; Drop, i.e., block, and do not return a connection error to the service device (loT device) that initiates the connection request.
[0151] Optionally, the following four examples of management attributes are given. Of course, management attributes are not limited to the following four examples. Management attributes include at least one of the following:
[0152] (1) Management attributes include first-class management attributes, which include connection management attributes.
[0153] Among them, the first type of management attributes includes: target node and behavior; or, the first type of management attributes includes: target node, behavior and connection type; or, the first type of management attributes includes: target node, behavior and access address; or, the first type of management attributes includes: target node, behavior and target security domain; or, the first type of management attributes includes: target node, behavior, connection type and access address; or, the first type of management attributes includes: target node, behavior, connection type and target security domain; or, the first type of management attributes includes: target node, behavior, access address and target security domain; or, the first type of management attributes includes: target node, behavior, connection type, access address and target security domain.
[0154] For example, if a first-category management attribute includes: target node 001, behavior allowed, and connection type LAN, the gateway device determines the target security domain based on the security domain where the first control device resides and allows the first service device access to the LAN based on the management attribute. The first service device is the device with node ID 001 in the target security domain.
[0155] Exemplarily, when a gateway device generates firewall rules based on management attributes, it needs to determine the device address of the target device based on the management attributes. Because the gateway device maintains a binding relationship between the security domain identifier, node identifier, and device address, that is, the gateway device stores the device address of the service device determined based on the security domain identifier and node identifier. The gateway device can determine the device address of the node within the security domain based on the security domain identifier and node identifier; the gateway device can also determine the security domain identifier to which the service device belongs and the node identifier of the service device within the security domain based on the device address.
[0156] Therefore, in an optional embodiment, when the management attributes include the target node (node identifier) and the target security domain (security domain identifier), the gateway device can determine the device address based on the security domain identifier and the node identifier. The management attributes may or may not include the target security domain. When the management attributes do not include the target security domain, the gateway device can determine the security domain where the control device is located as the target security domain. In another optional embodiment, when the management attributes include the target device (device address), the gateway device can directly determine the device address.
[0157] Exemplarily, the first type of management attributes may not include a target security domain. In this case, the gateway device defaults to assuming the target security domain is the security domain of the control device and determines the device address of the service device based on the security domain of the control device and the node identifier of the target node.
[0158] It should be noted that the device address can be at least one of an IP address and a MAC address. The MAC address of a service device is generally immutable. However, the IP address of a service device is variable. When the service device or gateway device restarts or reestablishes a connection, the gateway device reassigns the IP address to the service device. Therefore, if the device address includes an IP address, whenever the IP address is updated, the gateway device automatically updates the device address in the management properties and the corresponding firewall rules.
[0159] (2) Management attributes include second-category management attributes, and the second-category management attributes include connection management attributes.
[0160] Among them, the second category of management attributes includes: target device and behavior; or, the second category of management attributes includes: target device, behavior and connection type; or, the second category of management attributes includes: target device, behavior and access address; or, the second category of management attributes includes: target device, behavior and target security domain; or, the second category of management attributes includes: target device, behavior, connection type and access address; or, the second category of management attributes includes: target device, behavior, connection type and target security domain; or, the second category of management attributes includes: target device, behavior, access address and target security domain; or, the second category of management attributes includes: target device, behavior, connection type, access address and target security domain.
[0161] For example, a second-class management attribute includes: target device 001, behavior is allowed, connection type is LAN, and access address is 002. The gateway device allows the first service device to access the LAN address 002 according to the management attribute. The first service device is the device with address 001.
[0162] (3) Management attributes include third-category management attributes, and the third-category management attributes include blacklist management attributes.
[0163] Among them, the third type of management attributes includes: target node; or, the third type of management attributes includes: target node and connection type; or, the third type of management attributes includes: target node and target security domain; or, the third type of management attributes includes: target node and access address; or, the third type of management attributes includes; target node, access address and target security domain; or, the third type of management attributes includes: target node, connection type and target security domain; or, the third type of management attributes includes: target node, connection type and access address; or, the third type of management attributes includes: target node, connection type, access address and target security domain.
[0164] For example, a third-category management attribute includes: target node 001, target security zone 002, connection type WAN, and access address 003. Based on this management attribute, the gateway device blocks the first service device, which is a device with node ID 001 in a security zone with security zone ID 002, from accessing WAN address 003.
[0165] For example, the third type of management attributes may include a target security domain. Using the third type of management attributes, the control device can send management attributes of service devices in other security domains (not the security domain where the control device resides) to the gateway device. For example, if the control device belongs to the first security domain, the control device can send the third type of management attributes, where the target security domain in the third type of management attributes is the second security domain.
[0166] (4) Management attributes include the fourth type of management attributes, and the fourth type of management attributes include blacklist management attributes.
[0167] Among them, the fourth type of management attributes includes: target device; or, the fourth type of management attributes includes: target device and connection type; or, the fourth type of management attributes includes: target device and access address; or, the fourth type of management attributes includes: target device, connection type and access address.
[0168] For example, a third-category management attribute includes: target device 001, connection type WAN, and the gateway device blocks the first service device from accessing the WAN based on the management attribute. The first service device is the device with address 001.
[0169] Exemplarily, the management attributes are stored in a connection management list, and the control device can obtain the network connection management status of the service device by reading the connection management list. It should be noted that since the control device can only identify the node identifiers within the security domain to which it belongs, the control device cannot identify the node identifiers of other security domains (the control device cannot identify which device it is based on other security domain identifiers and node identifiers). Therefore, for management attributes that use target nodes to identify service devices (for example, first-class management attributes, third-class management attributes), the control device cannot identify the node identifiers of other security domains, and therefore cannot perform network connection management for nodes in other security domains. For management attributes that use target devices (device addresses) to identify service devices (for example, second-class management attributes, fourth-class management attributes), the control device can identify the service device and perform network connection management on it.
[0170] Exemplarily, in order to enable all control devices to identify the service devices in the connection management list, the gateway device may also replace the target node with the target device (device address) and store it in the connection management list when receiving the first type of management attributes and the third type of management attributes; or, after adding the target device (device address) to the first type of management attributes and the third type of management attributes, store it in the connection management list.
[0171] In summary, by storing the management attributes of the service device in the gateway device, the gateway device manages the network connection of the service device according to the management attributes of the service device, thereby realizing network connection management of the service device and controlling the network access of the service device to various networks.
[0172] Based on the solutions shown in FIG. 4 and FIG. 5 , in one possible case, the gateway device generates corresponding firewall rules according to the management attributes in the connection management list.
[0173] Please refer to Figure 6, which shows a flow chart of a method for managing a connection of a service device provided by one embodiment of the present application. This method can be interactively executed by a gateway device and a first control device; for example, the gateway device can be the gateway device 140 in the network architecture shown in Figure 1, and the first control device can be the control device 120 in the network architecture shown in Figure 1. The method can include the following steps:
[0174] Step 410: The first control device adds a first management attribute of the service device in the first security domain to the gateway device.
[0175] The gateway device receives a first management attribute of a service device added by the first control device in a first security domain; wherein the first security domain is the security domain where the first control device is located.
[0176] Optionally, the first control device may add the management attributes of the service device to the gateway device by sending a command or performing a write operation.
[0177] (1) The first control device sends an add management attribute command to the gateway device. The gateway device receives the add management attribute command sent by the first control device. The add management attribute command is used to add a first management attribute of the service device in the first security domain to the connection management list. The gateway device adds the first management attribute to the connection management list in accordance with the add management attribute command.
[0178] The Add Management Attribute command is used to add management attributes to the connection management list.
[0179] Among them, the add management attribute command includes at least one of the following parameters: target node, used to indicate the identification information of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0180] The add management attribute command may include at least a target node and a connection type. The target node may also be replaced by a target device. That is, the add management attribute command includes: a target node and a connection type;
[0181] Or, add a management attribute command including: target node, connection type, and target security domain;
[0182] Or, add management attribute commands including: target node, connection type and access address;
[0183] Alternatively, the command to add management attributes includes: target node, target security domain, connection type, and access address.
[0184] For example, when the add management attribute command includes: target node is 001, target security domain is 002, connection type is WAN, and access address is 003, the management attributes generated by the gateway device according to the add management attribute command include: target node is 001, target security domain is 002, connection type is WAN, and access address is 003, and the management attributes are added to the connection management list.
[0185] Optionally, the add management attribute command may further include a behavior. When the add management attribute command includes a behavior, the gateway device generates a connection management attribute based on the added management attribute; when the add management attribute command does not include a behavior, the gateway device generates a blacklist management attribute based on the added management attribute.
[0186] Optionally, the gateway device may also feed back a first command response of the add management attribute command to the first control device, where the first command response is used to feed back an execution result of the add management attribute command, including: addition success or addition failure.
[0187] (2) The first control device sends a delete management attribute command to the gateway device. The gateway device receives the delete management attribute command sent by the first control device. The delete management attribute command is used to delete the management attribute from the connection management list. The gateway device deletes the corresponding management attribute from the connection management list according to the delete management attribute command.
[0188] The delete management attribute command is used to delete management attributes in the connection management list.
[0189] Among them, the command to delete management attributes includes at least one of the following parameters: target node, used to indicate the identification information of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0190] The delete management attribute command may include at least a target node. The target node may also be replaced by a target device. That is, the delete management attribute command includes: the target node; or, the delete management attribute command includes: the target node and the connection type; or, the delete management attribute command includes: the target node and the target security domain; or, the delete management attribute command includes: the target node and the access address; or, the delete management attribute command includes: the target node, the access address, and the target security domain; or, the delete management attribute command includes: the target node, the connection type, and the target security domain; or, the delete management attribute command includes: the target node, the connection type, and the access address; or, the delete management attribute command includes: the target node, the target security domain, the connection type, and the access address.
[0191] For example, if the add management attribute command includes: target node 001, target security zone 002, connection type WAN, and access address 003, the gateway device searches the connection management list for the following management attributes: target node 001, target security zone 002, connection type WAN, and access address 003. If the gateway device successfully finds the management attribute, it deletes it from the connection management list; if it fails to find the management attribute, the command fails.
[0192] Optionally, the delete management attribute command may also include an action. When the delete management attribute command includes an action, the gateway device deletes the corresponding connection management attribute based on the deleted management attribute. When the delete management attribute command does not include an action, the gateway device deletes the corresponding blacklist management attribute based on the deleted management attribute.
[0193] Optionally, the gateway device may also provide a second command response to the delete management attribute command to the first control device. The second command response is used to provide feedback on the execution result of the delete management attribute command. The execution result includes: deletion success or deletion failure. When the execution result includes deletion failure, the execution result may also include information indicating the reason for the failure.
[0194] (3) The first control device writes the first management attribute to the gateway device. The gateway device receives the first management attribute written by the first control device, where the first management attribute is a management attribute of the device in the first security domain.
[0195] Optionally, the first control device may use any of the above methods (add management attribute command, delete management attribute command, write) to add the management attributes of the service device to the gateway device.
[0196] Optionally, when the first control device does not have permission to write the management attribute, the first control device may enable the gateway device to add the management attribute by issuing an add management attribute command; or enable the gateway device to delete the management attribute by issuing a delete management attribute command.
[0197] Optionally, when the first control device has permission to write the management attribute, the first control device may directly write the management attribute to the gateway device.
[0198] Optionally, when the management attributes are read-only, the control device can request the gateway device to modify the management attributes of the service device using the Add Management Attribute command or the Delete Management Attribute command. When the management attributes allow the control device to directly write, the control device can directly write the management attributes of the service device to the gateway device.
[0199] Step 420: The gateway device generates a firewall rule based on the management attributes of the service device in the gateway device.
[0200] Optionally, the gateway device generates corresponding firewall rules according to the management attributes in the connection management list.
[0201] Optionally, referring to FIG2 , the firewall rules include at least one of: name, protocol, source zone, source address, source port, output zone, access address (destination address), access port, behavior, and connection type.
[0202] Optionally, when the management attribute includes a target node, the gateway device determines the device address of the service device according to the security domain where the first control device is located and the target node, and determines the source address of the firewall rule according to the device address.
[0203] Optionally, when the management attributes include a target node and a target security domain, the gateway device determines a device address of the service device according to the target node and the target security domain, and determines a source address of the firewall rule according to the device address.
[0204] Optionally, in a case where the management attribute includes a target device, the gateway device determines the target device as a source address of the firewall rule.
[0205] Optionally, in a case where the management attribute includes a connection type, the gateway device determines the connection type of the management attribute as the connection type of the firewall rule.
[0206] Optionally, in a case where the management attribute includes a behavior, the gateway device determines the behavior of the management attribute as the behavior of the firewall rule.
[0207] Optionally, in a case where the management attribute does not include a behavior, the gateway device determines the behavior of the firewall rule as blocking.
[0208] Optionally, in a case where the management attribute includes an access address, the gateway device determines the access address of the management attribute as the access address (target address) of the firewall rule.
[0209] Optionally, when the gateway device is a sub-gateway in a multi-gateway network and the management attribute is used to allow or block access to an external network, a firewall rule is generated, and the firewall rule includes a target address that is an intranet address of a main gateway in the multi-gateway network.
[0210] In the case where the management attribute is used to allow or block access to an external network, the connection type in the management attribute may be a wide area network (WAN) or a local area network (LAN).
[0211] For example, as shown in Figure 7, when the WAN port of the sub-gateway is connected to the main gateway, the connection type in the management properties can be set to WAN; as shown in Figure 8, when the LAN port of the sub-gateway is connected to the main gateway, the connection type in the management properties can be set to LAN. This application does not limit this, and this embodiment only uses the example of setting the connection type to WAN.
[0212] That is, when the gateway device is a sub-gateway in a multi-gateway network and the management attribute includes a connection type of WAN, a firewall rule is generated, and the firewall rule includes a target address that is the intranet address of the main gateway in the multi-gateway network.
[0213] Optionally, when the gateway device is a master gateway in a multi-gateway network and the management attribute includes that the connection type is a wide area network, a firewall rule is generated, and the firewall rule includes that the target address is an address of the wide area network.
[0214] Exemplarily, the primary gateway is a gateway that enables Internet Gateway, ie, enables the ability to connect to the Internet.
[0215] Exemplarily, when the gateway device is a sub-gateway in a multi-gateway network, as shown in FIG7 , the WAN port of the main gateway is connected to the external network, and the WAN port of the sub-gateway is connected to the LAN port of the main gateway; or, as shown in FIG8 , the LAN port of the sub-gateway is connected to the LAN port of the main gateway.
[0216] For example, when a gateway device is a sub-gateway in a multi-gateway network, it accesses the WAN through the main gateway. If the gateway device is a sub-gateway, the gateway device controls the service device's access to the WAN by controlling network access between the device and the main gateway (where the target address is the main gateway's intranet address) based on firewall rules generated by management attributes. If the gateway device is a main gateway, the gateway device can directly control network access between the service device and the WAN (where the target address is the WAN address) based on firewall rules generated by management attributes.
[0217] In summary, the control device can add the service device's management attributes in the security domain to the gateway device, allowing the gateway device to manage the service device's network connection based on these attributes. Connection management policies are set at the Matter protocol layer, and the gateway device automatically generates firewall rules based on the Matter protocol layer's management policies to manage the service device's network connection. This allows the gateway device to support the control device in setting access rules for Matter devices on the network.
[0218] Based on the solutions shown in FIG. 4 , FIG. 5 or FIG. 6 , in one possible case, when the management attribute of the service device changes, the gateway device may send a management attribute change notification to the control device of the corresponding security domain.
[0219] Please refer to Figure 9, which shows a flow chart of a method for connection management of a service device provided by one embodiment of the present application. The method can be interactively executed by a gateway device and a first control device; for example, the gateway device can be the gateway device 140 in the network architecture shown in Figure 1, and the first control device can be the control device 120 in the network architecture shown in Figure 1. The method can include the following steps:
[0220] Step 430: The gateway device sends a first change notification to the first control device of the first security domain. The first change notification is used to notify the service device of the change of the management attribute in the first security domain.
[0221] The first control device receives a first change notification sent by the gateway device.
[0222] Optionally, step 430 may be performed after step 410, and / or, step 430 may be performed after step 420. Step 430 may be performed after step 310.
[0223] The first change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device whose management attributes are to be modified; an administrator security domain identifier, used to indicate the identification information of the security domain to which the control device whose management attributes are to be modified belongs; an initial value, used to indicate the management attributes before the change; a new value, used to indicate the management attributes after the change; a modified value, used to indicate the modified management attributes; and a modification type, used to indicate the type of modification operation.
[0224] Optionally, the modification type includes: add or delete.
[0225] For example, if the first change notification is issued due to the first control device adding the first management attribute, the first change notification may include: the node identifier of the first control device in the first security domain, the first security domain identifier, the initial value is 0, and the new value is the first management attribute.
[0226] In an optional embodiment, based on the solution shown in Figure 9 , the control device needs to pre-subscribe to the change notification of the management attribute. Referring to Figure 10 , before step 430 , steps 401 and 402 are included, and step 430 includes step 431 .
[0227] Step 401: A first control device sends a request for a subscription management attribute change notification to a gateway device.
[0228] Optionally, the first control device sends a request to the gateway device to subscribe to notifications of changes to management attributes of the first security domain.
[0229] Exemplarily, the control device may also subscribe to management attribute change notifications by default.
[0230] Step 402: The gateway device receives a request from a first control device for notification of a change in a subscription management attribute.
[0231] The gateway device subscribes to management attribute change notifications for the first control device. Alternatively, the gateway device subscribes to management attribute change notifications of the first security domain for the first control device.
[0232] Step 431 : When the first control device subscribes to a change notification of a management attribute, the gateway device sends a first change notification to the first control device in the first security domain.
[0233] The first control device receives a first change notification sent by the gateway device when the first control device subscribes to a change notification of a management attribute.
[0234] Optionally, when the management attribute of a device in the first security domain changes, the gateway device sends a first change notification to all control devices in the first security domain that have subscribed to the change notification.
[0235] In summary, the control device can subscribe to management attribute change notifications from the gateway device. When the management attributes of a service device in a security domain change, the gateway device can send a change notification to the control device in the security domain that has subscribed to change notifications to notify the service device of the change.
[0236] Based on the solutions shown in Figures 4 and 5 above, in one possible scenario, when the management attributes of a service device within a security domain change, the gateway device can automatically search for other security domains to which the device belongs and synchronously add the management attributes of the service device in other security domains.
[0237] Please refer to Figure 11, which shows a flow chart of a connection management method for a service device provided by an embodiment of the present application. The method can be interactively executed by a gateway device and a first control device; for example, the gateway device can be the gateway device 140 in the network architecture shown in Figure 1, and the first control device can be the control device 120 in the network architecture shown in Figure 1. The method can include the following steps:
[0238] Step 410: The first control device adds a first management attribute of the service device in the first security domain to the gateway device.
[0239] Step 420: The gateway device generates a firewall rule based on the management attributes of the service device in the gateway device.
[0240] Step 440: If the service device belongs to the second security domain, the gateway device adds a second management attribute of the service device in the second security domain.
[0241] The second management attribute is determined based on the first management attribute.
[0242] When the management attributes of the service device in the first security domain are changed, the gateway device can automatically search for other security domains to which the service device belongs, and synchronize the new management attributes to the other security domains.
[0243] Optionally, before step 440, the gateway device may query the device address of the service device and search for other security domains to which the device belongs based on the device address. For example, the first management attribute includes a first target node, which includes the node identifier of the service device in the first security domain; the gateway device determines the address of the service device based on the first security domain and the first target node; and based on the service device address, queries the second security domain and second target node to which the service device belongs, which includes the node identifier of the service device in the second security domain. For another example, the first management attribute includes a first target device; the gateway device queries the second security domain and second target node to which the service device belongs based on the first target device.
[0244] For example, the first management attributes include: a first node identifier (target node), a first security domain identifier (target security domain), a connection type of WAN, and a behavior of blocking. The gateway device then determines the device address of the service device based on the first node identifier and first security domain identifier in the first management attributes; finds based on the device address that the service device also belongs to the second security domain; and obtains the second node identifier of the service device in the second security domain. The gateway device generates second management attributes based on the first management attributes, the second security domain identifier of the second security domain, and the second node identifier. The second management attributes include: a second node identifier, a second security domain identifier, a connection type of WAN, and a behavior of blocking. The gateway device adds the second management attributes to the connection management list.
[0245] Optionally, after the gateway device adds the second management attribute, it is not necessary to generate a corresponding firewall rule according to the second management attribute.
[0246] In an optional embodiment, the first control device deletes a first management attribute of the service device in the first security domain to the gateway device. The gateway device deletes a firewall rule corresponding to the first management attribute. If the service device belongs to a second security domain, the gateway device deletes a second management attribute of the device in the second security domain.
[0247] That is, when the control device deletes the management attributes of a service device in one security domain, the gateway device will automatically delete the corresponding management attributes of the service device in other security domains.
[0248] To sum up, when the first control device in the first security domain changes the management attributes of the service device in the first security domain, the gateway device can automatically search for other security domains to which the service device belongs, and synchronously add the management attributes of the service device in other security domains based on the management attributes in the first security domain, so that the management attributes of the service device can achieve real-time adaptive adjustment of multiple security domains.
[0249] Based on the solution shown in FIG. 11 , in one possible scenario, when the management attributes of other security domains of the service device change, the gateway device may send a change notification to the control devices of the other security domains.
[0250] Please refer to Figure 12, which shows a flow chart of a method for managing a connection of a service device provided by one embodiment of the present application. This method can be interactively executed by a gateway device, a first control device, and a second control device. For example, the gateway device can be the gateway device 140 in the network architecture shown in Figure 1, and the first control device and the second control device can be the control device 120 in the network architecture shown in Figure 1. The method can include the following steps:
[0251] Step 410: The first control device adds a first management attribute of the service device in the first security domain to the gateway device.
[0252] Step 420: The gateway device generates a firewall rule based on the management attributes of the service device in the gateway device.
[0253] Step 440: If the service device belongs to the second security domain, the gateway device adds a second management attribute of the service device in the second security domain.
[0254] Step 450: The gateway device sends a second change notification to the second control device in the second security domain.
[0255] Optionally, the second change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device whose management attributes are to be modified; an administrator security domain identifier, used to indicate the identification information of the security domain to which the control device whose management attributes are to be modified belongs; an initial value, used to indicate the management attributes before the change; a new value, used to indicate the management attributes after the change; a modified value, used to indicate the modified management attributes; and a modification type, used to indicate the type of modification operation.
[0256] Optionally, the administrator node identifier in the second change notification is the node identifier of the first control device in the first security domain; the administrator security domain identifier is the security domain identifier of the first security domain where the first control device is located.
[0257] When the management attributes of a service device in one security domain change, causing corresponding changes in the management attributes in other security domains, the gateway device must also send a change notification to the control devices in other security domains to inform them of the change in management attributes.
[0258] Optionally, the second control device also needs to subscribe to management attribute change notifications. Prior to step 450, the gateway device receives a request from the second control device to subscribe to management attribute change notifications. Step 450 includes: if the second control device subscribes to management attribute change notifications, sending a second change notification to the second control device in the second security domain.
[0259] In summary, the control device can subscribe to management attribute change notifications from the gateway device. When the management attributes of a service device in a security domain change, the gateway device can send a change notification to the control device in the security domain that has subscribed to change notifications to notify the service device of the change.
[0260] Optionally, an exemplary embodiment of a first-type management attribute is provided. The first-type management attribute may also be referred to as a device connection management attribute.
[0261] Matter AP devices (gateway devices) add device connection management attributes to the Network Management Cluster to manage access to service devices on the network. See Table 1 for device connection management attributes.
[0262] Table 1
[0263] N indicates that the attribute data value is non-volatile and persists across reboots. F indicates that the attribute is fabric-scoped. A indicates that access to the attribute requires Admin privileges. For DeviceConnectStruct parameters, see Table 2.
[0264] Table 2
[0265] TargetNode is the target device for connection management and is represented by Node ID.
[0266] ConnectType comes from the map8 data type. Its encoding supports the connection types shown in Table 3.
[0267] Table 3
[0268] Among them, 0 represents a wide area network connection, 1 represents a local area network connection, and 2 represents a personal area network (such as Thread) connection.
[0269] For the definition of ActionEnum, see Table 4.
[0270] Table 4
[0271] When you need to explicitly allow or block the target device from accessing an address, use the optional attribute Destination to indicate this. If Destination is not included, access to all resources on the relevant network is allowed or blocked.
[0272] The AP also supports sending notifications when the DeviceConnectMgmt attribute changes. This is achieved through the DeviceConnectPolicyChanged (Device Connection Policy Changed) event in the AP. Control devices that subscribe to this event will receive the notification. For details about DeviceConnectPolicyChanged, see Table 5.
[0273] Table 5
[0274] A Priority of INFO indicates a general notification for the client. The S in the Access field indicates that the notification data is Fabric-Sensitive, meaning that the device can only receive data from this fabric and cannot see data from other fabrics. See Table 6 for the data included in the DeviceConnectPolicyChanged event.
[0275] Table 6
[0276] AdminNodeID is the Node ID of the control device whose connection management attributes are being modified. OriginalValue and NewValue are the values of the DeviceConnectMgmt attribute before and after the change, respectively.
[0277] As shown in Figure 13, the steps for configuring a Matter AP (gateway device) to prohibit a Matter device (service device / IoT device) from accessing the WAN include:
[0278] In step 501, the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet (network) through the AP.
[0279] Step 502: The AP checks the firewall rules and allows the device to access the Internet.
[0280] Step 503: The control device adds a new list item to the AP's DeviceConnectMgmt attribute:
[0281] TargetNode=0x1111_1111_1111_1111
[0282] ConnectType=1
[0283] Action=1.
[0284] Step 504: The AP determines the access fabric according to the administrator's write attribute operation, such as FabricID=0xFAB0_0000_0000_001D.
[0285] In step 505, the AP determines the IP address of the target device according to the FabricID and the NodeID. The address may be determined according to the AP's own network management record or the DNS-SD (Domain Name System-Service Discovery) discovery record.
[0286] Step 506: The AP sets a firewall rule, adding the target device address, access zone WAN, and Action=Drop.
[0287] Step 507: The AP sends a notification to the control device that subscribes to the DeviceConnectPolicyChanged event in the Fabric with FabricID=0xFAB0_0000_0000_001D.
[0288] In step 508, the AP determines the other fabric to which the device belongs based on the IP address of the target device. If the AP and the device are both in another fabric (FabricID=0xAAAA_AAAA_AAAA_AAAA), the AP can determine the NodeID=0x2222_2222_2222_2222 of the target device in this fabric based on its own network management records or DNS-SD discovery records.
[0289] Step 509: The AP adds a new list item to the DeviceConnectMgmt attribute:
[0290] TargetNode=0x2222_2222_2222_2222
[0291] ConnectType=1
[0292] Action=1
[0293] The access fabric of this list item is FabricID=0xAAAA_AAAA_AAAA_AAAA.
[0294] Step 510: The AP sends a notification to the control device that subscribes to the DeviceConnectPolicyChanged event in the Fabric with FabricID=0xAAAA_AAAA_AAAA_AAAA.
[0295] In step 511 , the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0296] In step 512, the AP checks the firewall rules and does not allow the device to access the Internet. The AP discards the data packets sent by the IoT device to the WAN and sent from the WAN with the IoT device as the destination address.
[0297] In summary, by adding a connection management feature set to an AP, the AP can support a control device setting access rules for a Matter device in the network. The control device can block or allow the device's access to the corresponding network through the AP by adding device connection management properties, and can also perform adaptive adjustments when multiple fabrics exist in the network.
[0298] Optionally, an exemplary embodiment of a second type of management attribute is given. The second type of management attribute may also be referred to as a device connection management attribute.
[0299] Matter AP devices (gateway devices) add device connection management attributes to the Network Management Cluster to manage access to service devices on the network. See Table 7 for device connection management attributes.
[0300] Table 7
[0301] N indicates that the attribute data value is nonvolatile and persists across reboots. F indicates that the attribute is fabric-scoped. A indicates that access to the attribute requires Admin privileges. For DeviceConnectStruct parameters, see Table 8.
[0302] Table 8
[0303] TargetDevice is the target device for connection management and is represented by the IP address of the target device.
[0304] ConnectType comes from the map8 data type. Its encoding supports the connection types shown in Table 9.
[0305] Table 9
[0306] Among them, 0 represents a wide area network connection, 1 represents a local area network connection, and 2 represents a personal area network (such as Thread (wired)) connection.
[0307] For the definition of ActionEnum, see Table 10.
[0308] Table 10
[0309] When you need to explicitly allow or block the target device from accessing an address, use the optional attribute Destination to indicate this. If Destination is not included, access to all resources on the relevant network is allowed or blocked.
[0310] The AP also supports sending notifications when the DeviceConnectMgmt attribute changes. This is achieved through the DeviceConnectPolicyChanged (Device Connection Policy Changed) event in the AP. Control devices that subscribe to this event will receive the notification. For details about DeviceConnectPolicyChanged, see Table 11.
[0311] Table 11
[0312] A Priority of INFO indicates a general notification for the client. The S in the Access field indicates that the notification data is Fabric-Sensitive, meaning that the device can only receive data from this fabric and cannot see data from other fabrics. See Table 12 for the data included in the DeviceConnectPolicyChanged event.
[0313] Table 12
[0314] AdminNodeID is the Node ID of the control device whose connection management attributes are being modified. OriginalValue and NewValue are the values of the DeviceConnectMgmt attribute before and after the change, respectively.
[0315] As shown in Figure 14, the steps for configuring a Matter AP (gateway device) to prohibit a Matter device (service device / IoT device) from accessing the WAN include:
[0316] In step 601, the IoT device (DeviceID=0x1111_1111_1111_1111) accesses the Internet (network) through the AP.
[0317] Step 602: The AP checks the firewall rules and allows the device to access the Internet.
[0318] Step 603: The control device adds a new list item to the AP's DeviceConnectMgmt attribute:
[0319] TargetDevice=0x1111_1111_1111_1111
[0320] ConnectType=1
[0321] Action=1.
[0322] In step 604, the AP determines the IP address of the target device, which can be determined based on the AP's own network management records or DNS-SD (Domain Name System-Service Discovery) discovery records. The AP sets a firewall rule, adding the target device address, access domain WAN, and Action = Drop.
[0323] Step 605: The AP sends a notification to the control device that subscribes to the DeviceConnectPolicyChanged event in the Fabric with FabricID=0xFAB0_0000_0000_001D.
[0324] In step 606 , the IoT device (DeviceID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0325] In step 607, the AP checks the firewall rules and does not allow the device to access the Internet. The AP discards the data packets sent by the IoT device to the WAN and sent from the WAN with the IoT device as the destination address.
[0326] In summary, by adding a connection management feature set to an AP, the AP can support a control device setting access rules for a Matter device in the network. The control device can block or allow the device's access to the corresponding network through the AP by adding device connection management properties, and can also perform adaptive adjustments when multiple fabrics exist in the network.
[0327] Optionally, an exemplary embodiment of a third type of management attribute is provided. The third type of management attribute may also be referred to as a blacklist management attribute.
[0328] Matter AP devices add device blacklist management attributes to the Network Management Cluster to manage access to service devices on the network. See Table 13 for blacklist management attributes.
[0329] Table 13
[0330] N indicates that the attribute data value is non-volatile and persists across reboots. A indicates that access to the attribute requires Admin privileges. For BlockedDeviceStruct parameters, see Table 14.
[0331] Table 14
[0332] TargetNode is the target device for connection management, represented by its Node ID. TargetFabric is the fabric to which the target device belongs.
[0333] ConnectType comes from the map8 data type. Its encoding supports the connection types shown in Table 15.
[0334] Table 15
[0335] Among them, 0 represents a wide area network connection, 1 represents a local area network connection, and 2 represents a personal area network (such as Thread (wired)) connection.
[0336] When you need to explicitly allow or block the target device from accessing an address, use the optional attribute Destination to indicate this. If Destination is not included, access to all resources on the relevant network is allowed or blocked.
[0337] The AP also supports sending notifications when the DenyList attribute changes. This is achieved through the DenyListChanged (blacklist update) event in the AP. Control devices that subscribe to this event will receive the notification. See Table 16 for DenyListChanged.
[0338] Table 16
[0339] Where Priority is INFO, it indicates that the event priority is a general notification for the client. For the data contained in the DenyListChanged event, see Table 17.
[0340] Table 17
[0341] AdminNodeID is the Node ID of the control device whose connection management attributes are being modified. AdminFabricID is the ID of the fabric to which the control device belongs. OriginalValue and NewValue are the values before and after the DenyList attribute is changed, respectively.
[0342] As shown in Figure 15, the steps for configuring a Matter AP (gateway device) to prohibit a Matter device (service device / IoT device) from accessing the WAN include:
[0343] In step 701, the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0344] Step 702: The AP checks the firewall rules and allows the device to access the Internet.
[0345] Step 703: The control device adds a new list item to the AP's DenyList attribute:
[0346] TargetFabric=0xFAB0_0000_0000_001D
[0347] TargetNode=0x1111_1111_1111_1111
[0348] ConnectType=1
[0349] In step 704, the AP determines the IP address of the target device according to the FabricID and the NodeID. The address may be determined according to the AP's own network management record or the DNS-SD discovery record.
[0350] Step 705: The AP sets a firewall rule, adding the target device address, access domain WAN, and Action=Drop.
[0351] Step 706: The AP sends a notification to the control device that subscribes to the DenyListChanged event.
[0352] In step 707 , the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0353] In step 708, the AP checks the firewall rules and does not allow the IoT device to access the Internet. The AP discards the data packets sent by the IoT device to the WAN and sent from the WAN with the IoT device as the destination address.
[0354] In summary, by adding a connection management feature set to the AP, the AP can support the control device to set access rules for a Matter device on the network. The control device can also add blacklist management attributes to prevent devices from accessing the corresponding network through the AP.
[0355] Optionally, an exemplary embodiment of a fourth type of management attribute is provided. The fourth type of management attribute may also be referred to as a blacklist management attribute.
[0356] Matter AP devices add device blacklist management attributes to the Network Management Cluster to manage access to service devices on the network. See Table 18 for blacklist management attributes.
[0357] Table 18
[0358] N indicates that the attribute data value is nonvolatile and persists across reboots. R indicates that the attribute is read-only. A indicates that access to the attribute requires Admin privileges. For BlockedDeviceStruct parameters, see Table 19.
[0359] Table 19
[0360] TargetDevice is the target device for connection management, represented by the device's IP address.
[0361] ConnectType is derived from the map8 data type. Its encoding supports the connection types shown in Table 20.
[0362] Table 20
[0363] Among them, 0 represents a wide area network connection, 1 represents a local area network connection, and 2 represents a personal area network (such as Thread (wired)) connection.
[0364] When you need to explicitly allow or block the target device from accessing an address, use the optional attribute Destination to indicate this. If Destination is not included, access to all resources on the relevant network is allowed or blocked.
[0365] As shown in Table 21, the AP device adds device connection management-related commands in the Network Management Cluster to change and modify the DenyList attribute.
[0366] Table 21
[0367] The AddBlokedDevice command is used to add a new list item to the DenyList attribute. Its parameters are shown in Table 22.
[0368] Table 22
[0369] After receiving the command, the AP determines the IP address of the target device based on the TargetFabric and TargetNode, and then forms a BlockedDeviceStruct with the device IP address, ConnectType, and optional Destination and adds it to the DenyList attribute.
[0370] The RemoveBlokedDevice command is used to delete a list item in the DenyList attribute. Its parameters are shown in Table 23.
[0371] Table 23
[0372] The AP also supports sending notifications when the DenyList attribute changes. This is achieved through the DenyListChanged (blacklist update) event in the AP. Control devices that subscribe to this event will receive the notification. See Table 24 for DenyListChanged.
[0373] Table 24
[0374] Priority=INFO indicates that the event priority is a general notification for the client. For the data contained in the DenyListChanged event, see Table 25.
[0375] Table 25
[0376] AdminNodeID is the Node ID of the control device whose connection management attributes are being modified. AdminFabricID is the ID of the fabric to which the control device belongs. ChangedValue is the list item being added or deleted. ChangeType is the type of operation being modified. For ChangeTypeEmun, see Table 26.
[0377] Table 26
[0378] As shown in Figure 16, the steps for configuring a Matter AP (gateway device) to prohibit a Matter device (service device / IoT device) from accessing the WAN include:
[0379] In step 801, the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0380] Step 802: The AP checks the firewall rules and allows the device to access the Internet.
[0381] Step 803: The control device sends an AddBlokedDevice command to the AP:
[0382] TargetNode=0x1111_1111_1111_1111
[0383] ConnectType=1
[0384] TargetFabric=0xFAB0_0000_0000_001D
[0385] Step 804: The AP returns a response after receiving the command.
[0386] In step 805, the AP determines the IP address of the target device according to the FabricID and NodeID. The address may be determined according to the AP's own network management record or DNS-SD discovery record, for example, the address is fe80::f515:576f:9783:3f30.
[0387] Step 806: The AP adds a list item to the DenyList attribute:
[0388] TargetDevice=fe80::f515:576f:9783:3f30
[0389] ConnectType=1
[0390] Step 807: The AP sets a firewall rule, adding the target device address, access zone WAN, and Action=Drop.
[0391] Step 808: The AP sends a notification to the control device that subscribes to the DenyListChanged event.
[0392] In step 709 , the IoT device (NodeID=0x1111_1111_1111_1111) accesses the Internet through the AP.
[0393] In step 810, the AP checks the firewall rules and does not allow the device to access the Internet. The AP discards the data packets sent by the IoT device to the WAN and sent from the WAN with the IoT device as the destination address.
[0394] In summary, by adding a connection management feature set to the AP, the AP can support the control device to set access rules for a Matter device on the network. The control device can add or delete commands to cause the gateway device to add or delete blacklist management attributes in the connection management feature set, thereby preventing devices from accessing the corresponding network through the AP.
[0395] Please refer to Figure 17, which shows a block diagram of a connection management device for a service device provided by one embodiment of the present application. The connection management device 800 of the service device has the functions of implementing the methods shown in Figures 4 to 16 above, which are performed by the gateway device. As shown in Figure 17, the device may include:
[0396] The management module 811 is configured to manage the network connection of the service device, wherein the management is performed based on the management attributes of the service device in the gateway device.
[0397] In an optional embodiment, the management attributes include at least one of the following parameters: target node, used to indicate the identification of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0398] In an optional embodiment, the management attributes include first-category management attributes;
[0399] Among them, the first type of management attributes includes: the target node and the behavior; or, the first type of management attributes includes: the target node, the behavior and the connection type; or, the first type of management attributes includes: the target node, the behavior and the access address; or, the first type of management attributes includes: the target node, the behavior and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the access address and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type, the access address and the target security domain.
[0400] In an optional embodiment, the first type of management attributes includes connection management attributes.
[0401] In an optional embodiment, the management attributes include second-category management attributes;
[0402] Among them, the second type of management attributes includes: the target device and the behavior; or, the second type of management attributes includes: the target device, the behavior and the connection type; or, the second type of management attributes includes: the target device, the behavior and the access address; or, the second type of management attributes includes: the target device, the behavior and the target security domain; or, the second type of management attributes includes: the target device, the behavior, the connection type and the access address; or, the second type of management attributes includes: the target device, the behavior, the connection type and the access address; or, the second type of management attributes includes: the target device, the behavior, the connection type and the target security domain; or, the second type of management attributes includes: the target device, the behavior, the access address and the target security domain; or, the second type of management attributes includes: the target device, the behavior, the connection type, the access address and the target security domain.
[0403] In an optional embodiment, the second type of management attributes includes connection management attributes.
[0404] In an optional embodiment, the management attributes include third-category management attributes;
[0405] Among them, the third type of management attributes includes: the target node; or, the third type of management attributes includes: the target node and the connection type; or, the third type of management attributes includes: the target node and the target security domain; or, the third type of management attributes includes: the target node and the access address; or, the third type of management attributes includes: the target node, the access address and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the access address; or, the third type of management attributes includes: the target node, the connection type, the access address and the target security domain.
[0406] In an optional embodiment, the third type of management attributes includes blacklist management attributes.
[0407] In an optional embodiment, the management attributes include a fourth type of management attributes;
[0408] Among them, the fourth type of management attributes includes: the target device; or, the fourth type of management attributes includes: the target device and the connection type; or, the fourth type of management attributes includes: the target device and the access address; or, the fourth type of management attributes includes: the target device, the connection type and the access address.
[0409] In an optional embodiment, the fourth type of management attributes includes blacklist management attributes.
[0410] In an optional embodiment, the connection type includes at least one of the following: a wide area network; a local area network; a personal area network.
[0411] In an optional embodiment, the behavior includes at least one of the following: blocking and returning a connection error; blocking without returning a connection error; allowing.
[0412] In an optional embodiment, the management attributes are stored in a connection management list of the gateway device.
[0413] In an optional embodiment, when the management attribute includes an access address and a behavior, the management includes: allowing or preventing the service device from accessing the access address according to the behavior.
[0414] In an optional embodiment, when the management attribute includes an access address, the management includes: preventing the service device from accessing the access address.
[0415] In an optional embodiment, when the management attribute does not include an access address and the management attribute includes a behavior and a connection type, the management includes: allowing or blocking the service device from accessing all access addresses of the connection type according to the behavior.
[0416] In an optional embodiment, when the management attribute does not include an access address but includes a connection type, the management includes: preventing the service device from accessing all access addresses of the connection type.
[0417] In an optional embodiment, the device further comprises:
[0418] The generating module 812 is configured to generate a firewall rule based on the management attribute of the service device in the gateway device.
[0419] In an optional embodiment, the generation module 812 is used to generate the firewall rules when the gateway device is a sub-gateway in a multi-gateway network and the management attributes are used to allow or prevent access to the external network, and the firewall rules include a target address that is the intranet address of the main gateway in the multi-gateway network.
[0420] In an optional embodiment, the generation module 812 is used to generate the firewall rules when the gateway device is the main gateway in a multi-gateway network and the management attributes include the connection type being a wide area network, and the firewall rules include the target address being the address of the wide area network.
[0421] In an optional embodiment, the device further comprises:
[0422] A first receiving module 813 is configured to receive a first management attribute of the service device in the first security domain added by the first control device;
[0423] The first security domain is the security domain where the first control device is located.
[0424] In an optional embodiment, the first receiving module 813 is used to receive an add management attribute command sent by the first control device, where the add management attribute command is used to add the first management attribute of the service device in the first security domain to the connection management list.
[0425] In an optional embodiment, the management module 811 is configured to add the first management attribute to the connection management list according to the add management attribute command.
[0426] In an optional embodiment, the add management attribute command includes at least one of the following parameters: target node, used to indicate the identifier of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0427] In an optional embodiment, the add management attribute command includes: the target node and the connection type;
[0428] Or, the add management attribute command includes: the target node, the connection type and the target security domain;
[0429] Alternatively, the add management attribute command includes: the target node, the connection type, and the access address;
[0430] Alternatively, the add management attribute command includes: the target node, the target security domain, the connection type, and the access address.
[0431] In an optional embodiment, the device further comprises:
[0432] The first receiving module 813 is configured to receive a delete management attribute command sent by the first control device, where the delete management attribute command is used to delete a management attribute from the connection management list.
[0433] In an optional embodiment, the management module 811 is configured to delete the corresponding management attribute from the connection management list according to the delete management attribute command.
[0434] In an optional embodiment, the deletion management attribute command includes at least one of the following parameters: target node, used to indicate the identification of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0435] In an optional embodiment, the deletion management attribute command includes: the target node; or, the deletion management attribute command includes: the target node and the connection type; or, the deletion management attribute command includes: the target node and the target security domain; or, the deletion management attribute command includes: the target node and the access address; or, the deletion management attribute command includes: the target node, the access address and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the access address; or, the deletion management attribute command includes: the target node, the target security domain, the connection type, the access address.
[0436] In an optional embodiment, the first receiving module 813 is configured to receive a first management attribute written by the first control device, where the first management attribute is a management attribute of the service device in the first security domain.
[0437] In an optional embodiment, the device further comprises:
[0438] The first sending module 814 is configured to send a first change notification to the first control device in the first security domain.
[0439] In an optional embodiment, the first receiving module 813 is configured to receive a request from the first control device to subscribe to a change notification of the management attribute.
[0440] In an optional embodiment, the first sending module 814 is configured to send the first change notification to the first control device in the first security domain when the first control device subscribes to the change notification of the management attribute.
[0441] In an optional embodiment, the first change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device for modifying the management attribute; an administrator security domain identifier, used to indicate the identifier of the security domain to which the control device for modifying the management attribute belongs; an initial value, used to indicate the management attribute before the change; and a new value, used to indicate the management attribute after the change.
[0442] The modification value is used to indicate the modified management attribute; the modification type is used to indicate the modification operation type.
[0443] In an optional embodiment, the management module 811 is configured to add a second management attribute of the service device in the second security domain if the service device belongs to the second security domain;
[0444] The second management attribute is determined based on the first management attribute.
[0445] In an optional embodiment, the management module 811 is configured to query the second security domain and the second target node to which the service device belongs according to the address of the service device, where the second target node includes a node identifier of the service device in the second security domain.
[0446] In an optional embodiment, the first management attribute includes a first target node, and the first target node includes a node identifier of the service device in the first security domain;
[0447] The management module 811 is configured to determine the address of the service device according to the first security domain and the first target node.
[0448] In an optional embodiment, the device further comprises:
[0449] The first sending module 814 is configured to send a second change notification to the second control device in the second security domain.
[0450] In an optional embodiment, the device further comprises:
[0451] The first receiving module 813 is configured to receive a request from the second control device to subscribe to a change notification of the management attribute.
[0452] In an optional embodiment, the first sending module 814 is configured to send the second change notification to the second control device in the second security domain when the second control device subscribes to the change notification of the management attribute.
[0453] In an optional embodiment, the second change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device to which the management attribute is modified; an administrator security domain identifier, used to indicate the identifier of the security domain to which the control device to which the management attribute is modified belongs; an initial value, used to indicate the management attribute before the change; a new value, used to indicate the management attribute after the change; a modified value, used to indicate the modified management attribute; and a modification type, used to indicate the type of modification operation.
[0454] Please refer to Figure 18, which shows a block diagram of a connection management device for a service device provided by one embodiment of the present application. The connection management device 900 of the service device has the functions of implementing the methods shown in Figures 4 to 16 above, which are performed by the first control device. As shown in Figure 18, the device may include:
[0455] The second sending module 901 is configured to add management attributes of the service device to the gateway device, where the management attributes are used to manage the network connection of the service device.
[0456] In an optional embodiment, the management attributes include at least one of the following parameters: target node, used to indicate the identification of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0457] In an optional embodiment, the management attributes include first-category management attributes;
[0458] Among them, the first type of management attributes includes: the target node and the behavior; or, the first type of management attributes includes: the target node, the behavior and the connection type; or, the first type of management attributes includes: the target node, the behavior and the access address; or, the first type of management attributes includes: the target node, the behavior and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the access address and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type, the access address and the target security domain.
[0459] In an optional embodiment, the first type of management attributes includes connection management attributes, and the connection management attributes are used to manage connection access of devices in the network.
[0460] In an optional embodiment, the management attributes include second-category management attributes;
[0461] Among them, the second type of management attributes includes: the target device and the behavior; or, the second type of management attributes includes: the target device, the behavior and the connection type; or, the second type of management attributes includes: the target device, the behavior and the access address; or, the second type of management attributes includes: the target device, the behavior, the connection type and the access address.
[0462] In an optional embodiment, the second type of management attributes includes connection management attributes.
[0463] In an optional embodiment, the management attributes include third-category management attributes;
[0464] Among them, the third type of management attributes includes: the target node; or, the third type of management attributes includes: the target node and the connection type; or, the third type of management attributes includes: the target node and the target security domain; or, the third type of management attributes includes: the target node and the access address; or, the third type of management attributes includes: the target node, the access address and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the access address; or, the third type of management attributes includes: the target node, the connection type, the access address and the target security domain.
[0465] In an optional embodiment, the third type of management attributes includes blacklist management attributes.
[0466] In an optional embodiment, the management attributes include a fourth type of management attributes;
[0467] Among them, the fourth type of management attributes includes: the target device; or, the fourth type of management attributes includes: the target device and the connection type; or, the fourth type of management attributes includes: the target device and the access address; or, the fourth type of management attributes includes: the target device, the connection type and the access address.
[0468] In an optional embodiment, the fourth type of management attributes includes blacklist management attributes.
[0469] In an optional embodiment, the connection type includes at least one of the following: a wide area network; a local area network; a personal area network.
[0470] In an optional embodiment, the behavior includes at least one of the following: blocking and returning a connection error; blocking without returning a connection error; allowing.
[0471] In an optional embodiment, the management attribute is stored in a connection management list of the gateway device.
[0472] In an optional embodiment, when the management attribute includes an access address and a behavior, the management includes: allowing or preventing the service device from accessing the access address according to the behavior.
[0473] In an optional embodiment, when the management attribute includes an access address, the management includes: preventing the service device from accessing the access address.
[0474] In an optional embodiment, when the management attribute does not include an access address and the management attribute includes a behavior and a connection type, the management includes: allowing or blocking the service device from accessing all access addresses of the connection type according to the behavior.
[0475] In an optional embodiment, when the management attribute does not include an access address but includes a connection type, the management includes: preventing the service device from accessing all access addresses of the connection type.
[0476] In an optional embodiment, the second sending module 901 is configured to add the first management attribute of the service device in the first security domain to the gateway device;
[0477] The first security domain is the security domain where the first control device is located.
[0478] In an optional embodiment, the second sending module 901 is used to send an add management attribute command to the gateway device, where the add management attribute command is used to add the first management attribute of the service device in the first security domain to the connection management list.
[0479] In an optional embodiment, the add management attribute command includes at least one of the following parameters: target node, used to indicate the identifier of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0480] In an optional embodiment, the add management attribute command includes: the target node and the connection type; or, the add management attribute command includes: the target node, the connection type and the target security domain; or, the add management attribute command includes: the target node, the connection type and the access address; or, the add management attribute command includes: the target node, the target security domain, the connection type, the access address.
[0481] In an optional embodiment, the second sending module 901 is configured to send a delete management attribute command to the gateway device, where the delete management attribute command is used to delete a management attribute from the connection management list.
[0482] In an optional embodiment, the deletion management attribute command includes at least one of the following parameters: target node, used to indicate the identification of the managed service device in the security domain; target device, used to indicate the address of the managed service device; target security domain, used to indicate the security domain to which the target node belongs; connection type; access address; behavior.
[0483] In an optional embodiment, the deletion management attribute command includes: the target node; or, the deletion management attribute command includes: the target node and the connection type; or, the deletion management attribute command includes: the target node and the target security domain; or, the deletion management attribute command includes: the target node and the access address; or, the deletion management attribute command includes: the target node, the access address and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the access address; or, the deletion management attribute command includes: the target node, the target security domain, the connection type, the access address.
[0484] In an optional embodiment, the second sending module 901 is configured to write a first management attribute to the gateway device, where the first management attribute is a management attribute of the service device in the first security domain.
[0485] In an optional embodiment, the device further includes:
[0486] The second receiving module 902 is configured to receive a first change notification sent by the gateway device.
[0487] In an optional embodiment, the second sending module 901 is configured to send a request for subscribing to a change notification of the management attribute to the gateway device.
[0488] In an optional embodiment, the second receiving module 902 is configured to receive the first change notification sent by the gateway device when the first control device subscribes to the change notification of the management attribute.
[0489] In an optional embodiment, the first change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device to which the management attribute is modified; an administrator security domain identifier, used to indicate the identifier of the security domain to which the control device to which the management attribute is modified belongs; an initial value, used to indicate the management attribute before the change; a new value, used to indicate the management attribute after the change; a modified value, used to indicate the modified management attribute; and a modification type, used to indicate the type of modification operation.
[0490] Please refer to FIG19 , which shows a schematic diagram of the structure of a computer device 1000 provided in one embodiment of the present application. The computer device 1000 may include: a processor 1001 , a receiver 1002 , a transmitter 1003 , a memory 1004 , and a bus 1005 .
[0491] The processor 1001 includes one or more processing cores. The processor 1001 executes various functional applications and information processing by running software programs and modules.
[0492] The receiver 1002 and the transmitter 1003 may be implemented as a communication component, which may be a communication chip, which may also be called a transceiver.
[0493] The memory 1004 is connected to the processor 1001 via a bus 1005 .
[0494] The memory 1004 may be used to store a computer program, and the processor 1001 may be used to execute the computer program to implement each step in the above method embodiment.
[0495] In addition, the memory 1004 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, including but not limited to: magnetic disk or optical disk, electrically erasable programmable read-only memory, erasable programmable read-only memory, static random access memory, read-only memory, magnetic memory, flash memory, and programmable read-only memory.
[0496] The process executed by the processor and / or transceiver in the computer device 1000 may refer to the steps executed by the gateway device or the first control device in any of the methods shown in FIG. 4 to FIG. 16 .
[0497] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. The computer program is loaded and executed by a processor to implement the various steps performed by the gateway device or the first control device in any of the methods shown in Figures 4 to 16 above.
[0498] The present application also provides a chip, which is used to run in a computer device so that the computer device executes each step performed by the gateway device or the first control device in any of the methods shown in Figures 4 to 16 above.
[0499] The present application also provides a computer program product, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform each step performed by the gateway device or the first control device in any of the methods shown in Figures 4 to 16 above.
[0500] The present application also provides a computer program, which is executed by a processor of a computer device to implement the various steps performed by the gateway device or the first control device in any of the methods shown in Figures 4 to 16 above.
Claims
1. A connection management method for a service device, characterized in that: The method is performed by a gateway device, and the method includes: The network connection of the service device is managed, and the management is performed based on the management attributes of the service device in the gateway device.
2. The method according to claim 1, characterized in that: The management attribute includes at least one of the following parameters: A target node is used to indicate the identification information of the managed service device in the security domain; a target device is used to indicate the address of the managed service device; a target security domain is used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
3. The method according to claim 2, characterized in that The management attributes include first-category management attributes; Among them, the first type of management attributes includes: the target node and the behavior; or, the first type of management attributes includes: the target node, the behavior and the connection type; or, the first type of management attributes includes: the target node, the behavior and the access address; or, the first type of management attributes includes: the target node, the behavior and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the access address and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type, the access address and the target security domain.
4. The method according to claim 3, characterized in that The first type of management attributes includes connection management attributes, and the connection management attributes are used to manage connection access of service devices in the network.
5. The method according to claim 2, characterized in that: The management attributes include second-category management attributes; Among them, the second type of management attributes includes: the target device and the behavior; or, the second type of management attributes includes: the target device, the behavior and the connection type; or, the second type of management attributes includes: the target device, the behavior and the access address; or, the second type of management attributes includes: the target device, the behavior, the connection type and the access address.
6. The method according to claim 5, characterized in that The second type of management attributes includes connection management attributes, and the connection management attributes are used to manage connection access of service devices in the network.
7. The method according to claim 2, characterized in that The management attributes include third-category management attributes; Among them, the third type of management attributes includes: the target node; or, the third type of management attributes includes: the target node and the connection type; or, the third type of management attributes includes: the target node and the target security domain: or, the third type of management attributes includes: the target node and the access address; or, the third type of management attributes includes: the target node, the access address and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the access address; or, the third type of management attributes includes: the target node, the connection type, the access address and the target security domain.
8. The method according to claim 7, characterized in that The third type of management attributes includes blacklist management attributes, and the blacklist management attributes are used to manage the connection access blacklist of the service device in the network.
9. The method according to claim 2, characterized in that: The management attributes include a fourth type of management attributes; Among them, the fourth type of management attributes includes: the target device; or, the fourth type of management attributes includes: the target device and the connection type; or, the fourth type of management attributes includes: the target device and the access address; or, the fourth type of management attributes includes: the target device, the connection type and the access address.
10. The method according to claim 9, characterized in that The fourth type of management attributes includes blacklist management attributes, and the blacklist management attributes are used to manage the connection access blacklist of the service device in the network.
11. The method according to any one of claims 2 to 10, characterized in that: The connection type includes at least one of the following: a wide area network; a local area network; a personal area network.
12. The method according to any one of claims 2 to 11, characterized in that: The behavior includes at least one of the following: blocking and returning a connection error; blocking without returning a connection error; allowing.
13. The method according to any one of claims 1 to 12, characterized in that: The management attributes are stored in a connection management list of the gateway device.
14. The method according to any one of claims 1 to 13, characterized in that: In the case that the management attribute includes an access address and a behavior, the management includes: allowing or preventing the service device from accessing the access address according to the behavior.
15. The method according to any one of claims 1 to 13, characterized in that: In a case where the management attribute includes an access address, the management includes: preventing the service device from accessing the access address.
16. The method according to any one of claims 1 to 13, characterized in that: In the case that the management attribute does not include an access address, and the management attribute includes a behavior and a connection type, the management includes: allowing or blocking the service device from accessing all access addresses of the connection type according to the behavior.
17. The method according to any one of claims 1 to 13, characterized in that: In a case where the management attribute does not include an access address and includes a connection type, the management includes: preventing the service device from accessing all access addresses of the connection type.
18. The method according to any one of claims 1 to 17, characterized in that: The method further comprises: A firewall rule is generated based on the management attribute of the service device in the gateway device.
19. The method according to claim 18, characterized in that The generating of the firewall rule based on the management attribute of the service device in the gateway device comprises: When the gateway device is a sub-gateway in a multi-gateway network and the management attribute is used to allow or prevent access to an external network, the firewall rule is generated, and the firewall rule includes a target address that is an intranet address of a main gateway in the multi-gateway network.
20. The method according to claim 18, characterized in that The generating of the firewall rule based on the management attribute of the service device in the gateway device comprises: When the gateway device is a master gateway in a multi-gateway network and the management attribute includes that the connection type is a wide area network, the firewall rule is generated, and the firewall rule includes that the target address is an address of the wide area network.
21. The method according to any one of claims 1 to 20, characterized in that: The method further comprises: receiving a first management attribute of the service device in the first security domain added by the first control device; The first security domain is the security domain where the first control device is located.
22. The method according to claim 21, characterized in that The receiving a first management attribute of the service device in the first security domain added by the first control device includes: An add management attribute command sent by the first control device is received, where the add management attribute command is used to add the first management attribute of the service device in the first security domain to a connection management list.
23. The method according to claim 22, characterized in that The method further comprises: According to the add management attribute command, the first management attribute is added to the connection management list.
24. The method according to claim 22 or 23, characterized in that The add management attribute command includes at least one of the following parameters: a target node, used to indicate the identification information of the managed service device in the security domain; a target device, used to indicate the address of the managed service device; A target security domain, used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
25. The method according to claim 24, characterized in that The add management attribute command includes: the target node and the connection type; or, the add management attribute command includes: the target node, the connection type and the target security domain; or, the add management attribute command includes: the target node, the connection type and the access address; or, the add management attribute command includes: the target node, the target security domain, the connection type, the access address.
26. The method according to any one of claims 21 to 25, characterized in that: The method further comprises: A delete management attribute command sent by the first control device is received, where the delete management attribute command is used to delete a management attribute in a connection management list.
27. The method according to claim 26, characterized in that The method further comprises: According to the delete management attribute command, the corresponding management attribute is deleted from the connection management list.
28. The method according to claim 26 or 27, characterized in that The delete management attribute command includes at least one of the following parameters: a target node, used to indicate the identification information of the managed service device in the security domain; a target device, used to indicate the address of the managed service device; A target security domain, used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
29. The method according to claim 28, characterized in that The deletion management attribute command includes: the target node; or, the deletion management attribute command includes: the target node and the connection type; or, the deletion management attribute command includes: the target node and the target security domain; or, the deletion management attribute command includes: the target node and the access address; or, the deletion management attribute command includes: the target node, the access address and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the access address; or, the deletion management attribute command includes: the target node, the target security domain, the connection type, the access address.
30. The method according to claim 21, characterized in that The receiving a first management attribute of the service device in the first security domain added by the first control device includes: A first management attribute written by the first control device is received, where the first management attribute is a management attribute of the service device in the first security domain.
31. The method according to any one of claims 21 to 30, characterized in that: The method further comprises: Sending a first change notification to the first control device of the first security domain, wherein the first change notification is used to notify the service device The management attribute of the device in the first security domain is changed.
32. The method according to claim 31, characterized in that The method further comprises: A request for the first control device to subscribe to a change notification of the management attribute is received.
33. The method according to claim 32, characterized in that The sending a first change notification to the first control device in the first security domain includes: In a case where the first control device subscribes to the change notification of the management attribute, the first change notification is sent to the first control device in the first security domain.
34. The method according to any one of claims 31 to 33, characterized in that: The first change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device to which the management attribute is modified; an administrator security domain identifier, used to indicate the identifier information of the security domain to which the control device to which the management attribute is modified belongs; An initial value, used to indicate the management attribute before the change; New value, used to indicate the changed management attribute; A modification value, which is used to indicate the modified management attribute; Modification type, used to indicate the type of modification operation.
35. The method according to any one of claims 21 to 34, characterized in that The method further comprises: In the case where the service device belongs to the second security domain, adding a second management attribute of the service device in the second security domain; The second management attribute is determined based on the first management attribute.
36. The method according to claim 35, characterized in that The method further comprises: The second security domain and the second target node to which the service device belongs are queried according to the address of the service device, where the second target node includes a node identifier of the service device in the second security domain.
37. The method according to claim 36, characterized in that The first management attribute includes a first target node, and the first target node includes a node identifier of the service device in the first security domain; the method further includes: An address of the service device is determined according to the first security domain and the first target node.
38. The method according to any one of claims 35 to 37, characterized in that: The method further comprises: A second change notification is sent to a second control device in the second security domain, where the second change notification is used to notify the service device of a change in a management attribute in the second security domain.
39. The method according to claim 38, characterized in that The method further comprises: A request for the second control device to subscribe to a change notification of the management attribute is received.
40. The method according to claim 39, characterized in that The sending a second change notification to the second control device in the second security domain includes: In a case where the second control device subscribes to the change notification of the management attribute, the second change notification is sent to the second control device in the second security domain.
41. The method according to any one of claims 38 to 40, characterized in that The second change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device to which the management attribute is modified; an administrator security domain identifier, used to indicate the identifier information of the security domain to which the control device to which the management attribute is modified belongs; An initial value, used to indicate the management attribute before the change; New value, used to indicate the changed management attribute; A modification value, which is used to indicate the modified management attribute; Modification type, used to indicate the type of modification operation.
42. A method for connection management of a service device, characterized in that: The method is performed by a first control device, and the method includes: Adding management attributes of the service device to the gateway device, wherein the management attributes are used to manage the network connection of the service device.
43. The method according to claim 42, characterized in that The management attribute includes at least one of the following parameters: a target node, used to indicate the identification information of the managed service device in the security domain; a target device, used to indicate the address of the managed service device; A target security domain, used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
44. The method according to claim 43, characterized in that The management attributes include first-category management attributes; Among them, the first type of management attributes includes: the target node and the behavior; or, the first type of management attributes includes: the target node, the behavior and the connection type; or, the first type of management attributes includes: the target node, the behavior and the access address; or, the first type of management attributes includes: the target node, the behavior and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the connection type and the access address; or, the first type of management attributes includes: the target node, the behavior, the access address and the target security domain; or, the first type of management attributes includes: the target node, the behavior, the connection type, the access address and the target security domain.
45. The method according to claim 44, characterized in that The first type of management attributes includes connection management attributes, and the connection management attributes are used to manage connection access of service devices in the network.
46. The method according to claim 43, characterized in that The management attributes include second-category management attributes; Wherein, the second type of management attributes includes: the target device and the behavior; or, the second type of management attributes includes: The target device, the behavior and the connection type; or, the second type of management attributes includes: the target device, the behavior and the access address; or, the second type of management attributes includes: the target device, the behavior, the connection type and the access address.
47. The method according to claim 46, characterized in that The second type of management attributes includes connection management attributes, and the connection management attributes are used to manage connection access of service devices in the network.
48. The method according to claim 43, characterized in that The management attributes include third-category management attributes; Among them, the third type of management attributes includes: the target node; or, the third type of management attributes includes: the target node and the connection type; or, the third type of management attributes includes: the target node and the target security domain: or, the third type of management attributes includes: the target node and the access address; or, the third type of management attributes includes: the target node, the access address and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the target security domain; or, the third type of management attributes includes: the target node, the connection type and the access address; or, the third type of management attributes includes: the target node, the connection type, the access address and the target security domain.
49. The method according to claim 48, characterized in that The third type of management attributes includes blacklist management attributes, and the blacklist management attributes are used to manage the connection access blacklist of the service device in the network.
50. The method of claim 43, wherein: The management attributes include a fourth type of management attributes; Among them, the fourth type of management attributes includes: the target device; or, the fourth type of management attributes includes: the target device and the connection type; or, the fourth type of management attributes includes: the target device and the access address; or, the fourth type of management attributes includes: the target device, the connection type and the access address.
51. The method according to claim 50, characterized in that The fourth management attribute comprises a blacklist management attribute, and the blacklist management attribute is used to manage a connection access blacklist of a service device in the network.
52. The method according to any one of claims 43 to 51, characterized in that The connection type includes at least one of the following: a wide area network; a local area network; a personal area network.
53. The method according to any one of claims 43 to 52, characterized in that The behavior includes at least one of the following: blocking and returning a connection error; blocking without returning a connection error; allowing.
54. The method according to any one of claims 42 to 53, characterized in that The management attributes are stored in a connection management list of the gateway device.
55. The method according to any one of claims 42 to 54, characterized in that In the case that the management attribute includes an access address and a behavior, the management includes: allowing or preventing the service device from accessing the access address according to the behavior.
56. The method according to any one of claims 42 to 54, characterized in that In a case where the management attribute includes an access address, the management includes: preventing the service device from accessing the access address.
57. The method according to any one of claims 42 to 54, characterized in that In the case that the management attribute does not include an access address, and the management attribute includes a behavior and a connection type, the management includes: allowing or blocking the service device from accessing all access addresses of the connection type according to the behavior.
58. The method according to any one of claims 42 to 54, characterized in that In a case where the management attribute does not include an access address and includes a connection type, the management includes: preventing the service device from accessing all access addresses of the connection type.
59. The method according to any one of claims 42 to 58, characterized in that The adding the management attribute of the service device to the gateway device comprises: adding a first management attribute of the service device in the first security domain to the gateway device; The first security domain is the security domain where the first control device is located.
60. The method according to claim 59, characterized in that The adding a first management attribute of the service device in the first security domain to the gateway device comprises: Sending an add management attribute command to the gateway device, wherein the add management attribute command is used to add the first management attribute of the service device in the first security domain to a connection management list.
61. The method according to claim 60, characterized in that The add management attribute command includes at least one of the following parameters: a target node, used to indicate the identification information of the managed service device in the security domain; a target device, used to indicate the address of the managed service device; A target security domain, used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
62. The method according to claim 61, characterized in that The add management attribute command includes: the target node and the connection type; or, the add management attribute command includes: the target node, the connection type and the target security domain; or, the add management attribute command includes: the target node, the connection type and the access address; or, the add management attribute command includes: the target node, the target security domain, the connection type, the access address.
63. The method according to any one of claims 42 to 62, characterized in that The method further comprises: Send a delete management attribute command to the gateway device, wherein the delete management attribute command is used to delete the management attribute in the connection management list. sex.
64. The method according to claim 63, characterized in that The delete management attribute command includes at least one of the following parameters: a target node, used to indicate the identification information of the managed service device in the security domain; a target device, used to indicate the address of the managed service device; A target security domain, used to indicate the security domain to which the target node belongs; Connection type; access address; behavior.
65. The method according to claim 64, characterized in that The deletion management attribute command includes: the target node; or, the deletion management attribute command includes: the target node and the connection type; or, the deletion management attribute command includes: the target node and the target security domain; or, the deletion management attribute command includes: the target node and the access address; or, the deletion management attribute command includes: the target node, the access address and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the target security domain; or, the deletion management attribute command includes: the target node, the connection type and the access address; or, the deletion management attribute command includes: the target node, the target security domain, the connection type, the access address.
66. The method according to any one of claims 42 to 59, characterized in that The adding the management attribute of the service device to the gateway device includes: writing a first management attribute to the gateway device, where the first management attribute is a management attribute of the service device in the first security domain.
67. The method according to any one of claims 42 to 66, characterized in that The method further comprises: A first change notification sent by the gateway device is received, where the first change notification is used to notify the service device of a change in a management attribute in the first security domain.
68. The method according to claim 67, characterized in that The method further comprises: A request for subscribing to change notifications of the management attributes is sent to the gateway device.
69. The method according to claim 68, characterized in that The receiving a first change notification sent by the gateway device includes: In a case where the first control device subscribes to the change notification of the management attribute, the first change notification sent by the gateway device is received.
70. The method according to any one of claims 67 to 69, characterized in that The first change notification includes at least one of the following parameters: an administrator node identifier, used to indicate the node identifier of the control device to which the management attribute is modified; an administrator security domain identifier, used to indicate the identifier information of the security domain to which the control device to which the management attribute is modified belongs; Initial value, used to indicate the management attribute before the change; New value, used to indicate the changed management attribute; A modification value, which is used to indicate the modified management attribute; Modification type, used to indicate the type of modification operation.
71. A connection management device for a service device, characterized in that: The device comprises: A management module is used to manage the network connection of the service device, wherein the management is performed based on the management attributes of the service device in the gateway device.
72. A connection management device for a service device, characterized in that: The device comprises: The second sending module is used to add management attributes of the service device to the gateway device, where the management attributes are used to manage the network connection of the service device.
73. A computer device, characterized in that: The computer device includes a processor, a memory and a transceiver; The memory stores a computer program, and the processor executes the computer program so that the computer device implements the connection management method for the service device as described in any one of claims 1 to 70 above.
74. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and the computer program is used to be executed by a processor to implement the connection management method for a service device as described in any one of claims 1 to 70.
75. A chip, characterized in that: The chip is used to run in a computer device so that the computer device executes the connection management method of the service device as described in any one of claims 1 to 70.
76. A computer program product, characterized in that The computer program product includes computer instructions, which are stored in a computer-readable storage medium; the processor of the computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, so that the computer device executes the connection management method of the service device as described in any one of claims 1 to 70.
77. A computer program, characterized in that The computer program is executed by a processor of a computer device to implement the connection management method of a service device as described in any one of claims 1 to 70.